CVE-2020-12606

CRITICAL

DB Soft SGLAC <20.05.001 - SQL Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web frontend allows an attacker to run arbitrary SQL commands on the SQL Server. Command execution can be easily achieved by using the xp_cmdshell stored procedure.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.0364
EPSS Percentile 87.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
dbsoft/sglac < 20.05.001
Published Aug 17, 2020
Tracked Since Feb 18, 2026